Set up MX/Inline deployment
To use Email Security, you will need to have:
- A Cloudflare account ↗
 - A Zero Trust organization
 - A domain to protect
 
- Log in to Zero Trust ↗.
 - Select Email Security.
 - Select Overview. Select one of the following options:
 
- If you have not purchased Email Security, select Contact sales.
 - If you have not associated any integration, select Set up.
 - If you have associated an integration, but have not connected a domain, select Connect a domain.
 
- Select MX/Inline.
 - To start the MX/Inline configuration, you will need to have completed the prerequisite setup on your email provider's platform. Once you have completed this step, select I confirm that I have completed all the necessary requirements. Then, select Start configuration.
 
If you have verified zones on Cloudflare, continue with the following steps:
- Connect a domain: Select your domain. Then, select Continue.
 - Select position: This step allows you to choose where Email Security fits into your mail flow and configure position settings:
- Select position: Choose between:
- Sit first (hop count = 1): Email Security is the first server that receives the email. There are no other email scanners or services between the Internet and Cloudflare.
 - Sit in the middle (hop count > 1): Email Security sits anywhere other than the first position. Other servers receive emails before Email Security. There are other email scanners or email services in between.
 
 - Position settings: Refine how Email Security receives and forwards emails:
- Forwarding address: This is your mail flow next hop after Email Security. This value is auto-filled, but you can still change it.
 - Outbound TLS: Choose between:
- Forward all messages over TLS (recommended).
 - Forward all messages using opportunistic TLS.
 
 
 - Select Continue.
 
 - Select position: Choose between:
 - (Optional, select Skip for now to skip this step) Configure quarantine policy: Select dispositions to automatically prevent certain types of incoming messages from reaching a recipient's inbox.
 - (Optional) Update MX records:
- Email Security can automatically update MX records for domains that proxy traffic through Cloudflare. Under Your mail processing location, select your mail processing location.
 - You can also choose to allow Cloudflare to update MX records by selecting I confirm that I allow Cloudflare to update to the new MX records. When Email Security updates MX records, we replace your original MX records with Email Security MX records.
 - Select Continue.
 
 - Review details: Review your domain, then select Go to domains.
 
If you do not have domains with Cloudflare, the dashboard will display two options:
Selecting Add a domain to Cloudflare will redirect you to a new page where you will connect your domain to Cloudflare. Once you have entered an existing domain, select Continue.
Then, follow the steps to Set up MX/Inline.
- Add domains: Manually enter domain names.
 - Review all domains: Review all your domains, then select Continue.
 - Verify your domains: It may take up to 24 hours for your domains to be verified. Select Done.
 - Once your domains have been verified, the dashboard will display a message like this: You have verified domains ready to connect to Email Security. This means that you can now set up Email Security via MX/Inline.
 - Select Set up, then select MX/Inline.
 - Follow the steps to Initiate MX/Inline configuration.
 
Was this helpful?
- Resources
 - API
 - New to Cloudflare?
 - Products
 - Sponsorships
 - Open Source
 
- Support
 - Help Center
 - System Status
 - Compliance
 - GDPR
 
- Company
 - cloudflare.com
 - Our team
 - Careers
 
- 2025 Cloudflare, Inc.
 - Privacy Policy
 - Terms of Use
 - Report Security Issues
 - Trademark